Sub-processors
Every third party that can touch personal data on our behalf, what each one can actually see, and where it sits. 10 in total: 5 processing data today, and 5 named in advance but not yet live.
Last reviewed 8 August 2026. Forms Annex III of theData Processing Agreement.
Why some of these say "not yet in use"
The purpose of this list is to give you notice before a change rather than after, so the whole intended stack is named now with an honest status against each one. A provider only moves into the first table once it is genuinely processing data. Naming one early costs you nothing; naming one late takes away your chance to object.
Only providers that can process personal data are listed. Monitoring that sees no personal data is not a sub-processor, and padding this table with tooling would be noise rather than transparency.
In use today
| Provider | What it does | What it can see | Where |
|---|---|---|---|
| Hetzner Online GmbH | The physical servers that run the website, the billing API and our database, and that host customer sites Our database runs on the same servers and is not reachable from the public internet. | Everything stored in a hosted site; our own database of customer names, email addresses, countries, orders and invoices; and server logs including IP addresses | Germany, EU |
| Cloudflare, Inc. | DNS, CDN, TLS termination, firewall, bot challenge, and the tunnel that fronts our origin | Visitor IP addresses, request metadata, and inbound email to our own addresses | United States and a global edge network |
| Resend | Sending transactional email: receipts, payment notices, password resets | Recipient name and email address, and the content of the message | United States |
| Stripe Payments Europe, Ltd. | Card payments and payment-method storage Card details are entered on Stripe’s own pages and never reach our servers. Stripe also determines the VAT on each sale, so it sees the billing country and any VAT number given. | Name, email, billing address, country, and card details | Ireland, EU, with onward transfer to Stripe, Inc. in the United States |
| Google Ireland Ltd. (Gmail) | The mailbox that receives email sent to our published addresses Inbound mail is routed by Cloudflare and delivered into a Gmail mailbox. It is where a request sent to our privacy address arrives, so it is named here rather than left implicit. | Anything you send us: your name, email address, and the content of your message, including support requests, data protection requests and abuse reports | Ireland, EU, with onward transfer to Google LLC in the United States |
Contracted for launch, not yet in use
| Provider | What it will do | What it will see | Where |
|---|---|---|---|
| Backblaze B2 | Off-site backup storage Encrypted with AES-256 on our own server before upload, so Backblaze holds ciphertext and not readable content. | Encrypted backups of hosted sites and of our own database | United States |
| OVHcloud | A second, independent backup location held outside our main provider Deliberately a different company from Hetzner. Backups kept only inside the account that could be terminated are not backups. | Encrypted backups, as above | France, EU |
| Functional Software, Inc. (Sentry) | Recording application errors so they can be fixed | IP address, account identifier, and the request context attached to an error | United States, with an EU region available |
| Better Stack | Uptime monitoring and log storage | Server and application logs, which contain IP addresses | Czech Republic, EU |
| Grafana Labs | Metrics and log aggregation | Server and application logs, which contain IP addresses | EU region |
Changes to this list
Before we add or replace a sub-processor we email you 30 days beforehand. If you object on reasonable data protection grounds and we cannot resolve it, you can terminate the affected subscription and we refund the unused part of your term.
Updating this page is not notice. An email is notice. A page that changes quietly is how a sub-processor list becomes decoration.
Transfers outside the EEA
Where a provider above is outside the EEA we rely on an adequacy decision where one covers it, and on the European Commission's standard contractual clauses plus a transfer risk assessment otherwise. Website content itself is stored in the EU.
Questions: privacy@borgohost.com.